New Red Teaming Tool RedTiger Attacking Gamers and Discord Accounts in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RedTiger is an open-source red-teaming tool repurposed by attackers to steal sensitive data from Discord users and gamers. Released in 2025 on GitHub, RedTiger bundles penetration-testing utilities, including network scanners and OSINT tools. But its infostealer module has gone rogue, …

Arsen Launches Smishing Simulation to Help Companies Defend Against Mobile Phishing Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Paris, France, October 24th, 2025, CyberNewsWire Arsen, the cybersecurity company dedicated to helping organizations defend against social engineering, today introduced its new Smishing Simulation module: a feature designed to let companies run realistic, large-scale SMS phishing simulations across their teams. …

ChatGPT Atlas Stores OAuth Tokens Unencrypted Leads to Unauthorized Access to User Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability in OpenAI’s newly released ChatGPT Atlas browser reveals that it stores unencrypted OAuth tokens in a SQLite database with overly permissive file settings on macOS, potentially allowing unauthorized access to user accounts. This flaw, discovered by Pete …

WhatsApp Exploit Privately Disclosed To Meta At The Pwn2Own Ireland

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

At Pwn2Own Ireland 2025 hacking competition, cybersecurity researchers from Team Z3 have withdrawn their high-stakes demonstration of a potential zero-click remote code execution (RCE) vulnerability in WhatsApp, opting instead for a private coordinated disclosure to Meta. The event, held in …

Hackers Exploited 73 0-Day Vulnerabilities and Earned $1,024,750

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The hacking community celebrated the end of Pwn2Own Ireland 2025. Researchers demonstrated their skills by identifying 73 unique zero-day vulnerabilities across different devices. The event, hosted by the Zero Day Initiative (ZDI), distributed a staggering $1,024,750 in prizes, highlighting the …

New PhantomCaptcha RAT Weaponized PDFs to Deliver Malware Using ‘ClickFix’-Style Cloudflare Captcha Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated spearphishing campaign has emerged targeting humanitarian organizations and Ukrainian government agencies, leveraging weaponized PDF attachments and fake Cloudflare verification pages to distribute a dangerous WebSocket-based remote access trojan. The operation, first uncovered in early October 2025, demonstrates a …

Amazon Uncovers Root Cause of Major AWS Outage That Brokes The Internet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services (AWS), the backbone for countless websites and services, faced a severe outage last weekend that disrupted operations for millions. The incident, which unfolded in the early hours of October 20, 2025, exposed vulnerabilities in even the most …

Threat Actors Advancing Email Phishing Attacks to Bypass Security Filters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Email phishing attacks have reached a critical inflection point in 2025, as threat actors deploy increasingly sophisticated evasion techniques to circumvent traditional security infrastructure and user defenses. The threat landscape continues to evolve with the revival and refinement of established …

Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS). Identified as CVE-2025-59287, the issue stems from the deserialization of untrusted data in a legacy serialization mechanism, allowing …

Toys “R” Us Canada Confirms Data Breach – Customers Personal Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Toys “R” Us Canada has alerted customers to a significant data breach that potentially exposed their personal information, marking another blow to consumer trust in retail data security. In emails dispatched to affected individuals this morning, the popular toy retailer …